RALEIGH, N.C. — During a cybersecurity evaluation of OpenAI’s newest systems, the models did something researchers had never seen before, according to the company. Instead of staying inside a controlled environment, they found a way to reach the internet and then targeted another company’s systems in an attempt to complete their assigned objective. “This is a huge failure and a tremendous warning shot to all of society, that more action is necessary in this area,” said Duke University cybersecurity professor David Hoffman. Hoffman has been studying artificial intelligence and cybersecurity for more than two decades. He says this recent hack stems from the lack of governance over AI. “We should be worried that if, like any technology, if you were to say that you are not going to govern it at all, you're not going to have anybody other than the organization that's actually doing the development of the technology play a role to determine what the right safeguards are going to be. That's a recipe for disaster,” he said. OpenAI says the breach happened during internal testing of advanced AI agents designed to perform cybersecurity tasks. CEO Sam Altman called the breach a "significant security incident." Hoffman says it should be taken seriously. “This was a cybersecurity attack by OpenAI's tool that if a person had done it, they could be prosecuted,” he said. The company says the AI wasn’t trying to steal customer information. Instead, researchers say it was trying to get answers that would help it perform better. General manager of AI security at Checkpoint Cybersecurity Adam Ely says incidents like this happen all the time but never to this extent. “This is the first time at this scale that we've really seen this happen, that the world has been aware that this can happen,” Ely said.
Jul 24, 2026 · via spectrumlocalnews.com
Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. CISOs vs. Boards: Myth or Misunderstanding? Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide. The rumors are exaggerated. Executive boards aren't apathetic to security threats; they're often struggling with a cybersecurity language barrier. Increasingly disruptive cyberattacks require preventative and remediation efforts from positions across organizations, yet chief information security officers (CISOs) and IT teams feel unsupported by the powers that be. This adds pressure on the CISOs, as they fend off attacks and manage potentially devastating fallout. But attacks affect business operations, an organization's reputation, and can result in legal implications which require everyone to get on the same page. More companies are recognizing this, as the threat landscape intensifies and leadership is working to break down the stereotype that boards don't care about security. There is a misplaced perception that board directors sometimes deprioritize cybersecurity over speed and growth, says Edna Conway, chief operating and risk officer at TPO group and former chief security and risk officer at Microsoft. "In reality, strong directors care deeply; not only about cyber risks but about the business's people, its mission, and about what's going on 360 degrees outside of the organizations," Conway tells Dark Reading. Is Transparency Ever TMI? Transparency is one highly contentious point that has fueled claims that leadership doesn't prioritize security. A recent Checkmarx report found 95% of CISOs feel pressured by management and boards to suppress security issues found in their organizations. CISOs track and respond to threats in real time. The board's job is to focus on profits and growth. Disclosing a vulnerability or an attack, even an attempted one, can compromise business growth and that's
Jul 24, 2026 · via darkreading.com
AI Security Continue to Define Cybersecurity Evolution Cybersecurity this week centered on the expanding attack surface created by AI and increasingly sophisticated cybercrime. An unprecedented incident involving OpenAI models exploiting vulnerabilities raised new questions about AI safety, while ransomware operators adopted physical intimidation tactics through compromised printers and seasonal fraud campaigns continued targeting Mexican consumers. Ready? This is your Week in Cybersecurity! OpenAI Models Hack Hugging Face Servers US-based AI research lab OpenAI reported that two of its autonomous AI models escaped a restricted testing environment and exploited vulnerabilities in Hugging Face’s production infrastructure. The companies confirmed they are conducting a joint forensic investigation into the unprecedented incident. According to OpenAI, the activity involved OpenAI’s GPT-5.6 Sol model alongside an unreleased pre-release model operating with reduced security guardrails during an internal capabilities evaluation. Summer Travel Fraud in Mexico Up 3% Amid Cybercrime Surge Travel fraud in Mexico increased 3% during the summer vacation season compared to 2025, driven by fake digital offers and cloned websites targeting holiday consumers, according to data from the Mexico City Citizens' Council for Security and Justice. The fraudulent scheme, known locally as "montaviajes," capitalizes on online searches for discounted vacation packages, flights, and hotel bookings. Kaspersky Warns of Printer-Based Ransomware Tactic in LATAM Ransomware operators are adopting increasingly unconventional tactics to intensify pressure on victims. According to new research from Kaspersky, attacks targeting organizations in Mexico and Colombia found that cybercriminals not only encrypted systems using Microsoft's BitLocker encryption tool but also hijacked corporate printers to physically distribute ransom demands throughout affected organizations. Visibility Becomes a Key Security Layer in B2B Logistics Digital transformation has reshaped B2B logistics from a sequence of physical operations into an interconnected ecosystem where information moves as constantly as goods. Orders, inventory records, invoices, delivery confirmations and transportation routes now
Jul 24, 2026 · via mexicobusiness.news
Dive Brief: - North America accounts for the most internet-exposed industrial control systems (ICS) as of early 2026, with roughly 38% of all such devices located on the continent, according to the internet monitoring firm Censys. - Meanwhile, the number of publicly accessible AI tools is growing fast: Censys detected more than 294,000 IP addresses associated with AI services in early 2026, up from 183,000 in October 2025. - The data, from a preview of Censys’s annual internet exposure report, highlights the vast array of targets available to hackers who are intent on sabotaging critical infrastructure or subverting the AI tools on which companies increasingly rely. Dive Insight: Not only are AI services increasingly appearing on the public internet, but the products with the most significant vulnerabilities are the ones popping up most frequently. Censys detected 169% more instances of the AI agent-building tool Langflow over the past nine months, even as the software has accumulated 18 vulnerabilities (14 of them scored as high-severity, four of them seeing exploitation) since 2024. “Multiple unauthenticated remote code execution (RCE) vulnerabilities make any Internet-exposed instance a critical finding,” Censys said. The number of internet-exposed instances of another common AI tool, LiteLLM, nearly doubled during Censys’s observation window, even as hackers continue exploitating a pre-authentication SQL injection vulnerability. LiteLLM serves as a unified hub for connecting to commercial LLMs, meaning that a compromise of its data would expose a customer’s API keys for all of those services. The ICS landscape, as it appears in Censys’s data, is no less alarming. The number of internet-exposed ICS devices has grown from 129,000 in 2024 to 138,000 in early 2026, magnifying the danger facing communities around the world as the equipment powering their energy grids, hospitals and water supplies remain within easy reach of hackers. While the
Jul 24, 2026 · via cybersecuritydive.com
Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America. Europe's Multilingual Reality Exposes AI Security Gaps The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language. Not all languages are treated equally when it comes to AI model function and safety, and European organizations face a particular risk when it comes to this reality. The modern large language model (LLM) ecosystem relies heavily on natural language, whether a user is speaking to a chatbot, issuing specific instructions for software development, generating emails, or performing large-scale data analysis. This reliance is further illustrated through the wide range of prompt injection attacks that rely on language-based trickery. While leading models can process text in dozens to hundreds of languages, performance and safety capabilities vary dramatically between languages. Many of the less-supported languages, such as Welsh and Swahili, can answer only basic prompts and may make grammatical errors. Mainstream models like OpenAI's GPT, Google's Gemini, and Anthropic's Claude demonstrate strong performance in around 30 to 40 languages such as English, Arabic, Spanish, French, German, Japanese, Simplified Chinese, and Hindi. English is by far the language best supported by many AI models. English benefits both from disproportionate training data and from tokenization schemes that often represent English more efficiently than many other languages. Academic research shows that many LLMs perform logic, reasoning, coding, and math tasks best when prompted in English language, and many major AI labs conduct safety tuning, behavior alignment, and reinforcement using English-speaking annotators. There are exceptions to this rule. Chinese models like Qwen and DeepSeek outperform Western models when handling Chinese text and cultural context, and certain
Jul 24, 2026 · via darkreading.com
The Solar Energy Industries Association (SEIA) has released a new report outlining a roadmap to strengthen cybersecurity across the US solar and energy storage industry while supporting the continued expansion of domestic manufacturing. The publication comes as the country's solar and battery storage manufacturing capacity continues to grow, with US inverter manufacturing having nearly tripled since the end of 2024. Following the opening of a new inverter production facility in July, the United States is now tied as the world's second-largest manufacturer of inverters. The report addresses the growing cybersecurity challenges facing the energy sector and highlights the importance of secure technologies backed by resilient domestic supply chains. Developed in collaboration with industry and government stakeholders, it provides recommendations, best practices and resources to help companies improve cybersecurity preparedness across the solar and storage value chain. According to SEIA, the rapid deployment of solar and battery storage systems makes cybersecurity an increasingly critical component of energy security. The association argues that strengthening domestic manufacturing and supply chain resilience will help protect critical infrastructure while reducing exposure to evolving cyber threats. "As solar and storage continue to lead the way in adding new power capacity to the grid, cybersecurity must remain front and center," said Tim Pawlenty, president and CEO of SEIA. "From secure and resilient systems to expanding domestic manufacturing, this report lays out the actions our industry is taking to strengthen U.S. energy security, protect critical infrastructure, and stay ahead of emerging threats." Among its recommendations, the report calls for expanding domestic solar and storage manufacturing through more resilient supply chains, greater transparency and trusted production capacity. It also advocates establishing consistent cybersecurity practices across the industry, promoting national guidance for distributed energy resources, and improving information sharing and coordination to strengthen threat detection and risk communication throughout the
Jul 24, 2026 · via review-energy.com
Why investors poured $340 million into three Israeli cyber startups before anyone knew they existed Oak, Neo and Glow emerged from stealth within days of each other, reflecting a broader shift toward AI-native enterprise security. Three Israeli cybersecurity startups emerged from stealth within the space of a week, unveiling a combined $340 million in funding and underscoring where investors believe the next major battleground in enterprise security lies: protecting organizations as artificial intelligence reshapes corporate computing. The announcements, by Oak, Neo and Glow, were spread across eight days in July, creating the appearance of a sudden surge in funding for Israeli cybersecurity. In reality, the rounds were likely completed months earlier, reflecting investment decisions made well before the companies stepped into the spotlight. Taken together, however, the debuts offer a snapshot of how rapidly cybersecurity is being redefined by AI. While each company is attacking a different part of the enterprise stack, all three are built around the premise that conventional security products were designed for a world in which humans, rather than autonomous software, were making decisions inside corporate networks. The largest financing came from Glow, which emerged from stealth with $180 million at a $1.2 billion valuation after raising capital across three rounds in roughly a year. Founded in 2025 by executives from Meta, Snowflake and Claroty, the company is targeting the $40 billion endpoint security market, arguing that AI has fundamentally changed the nature of the corporate device. "With all the investment in cyber, attackers find new entry routes, and everything eventually ends up at the endpoint," said CEO and co-founder Roi Tiger. "If you understand how to use AI to deal with it before it happens and work proactively, you can provide a solution where prevention also reaches the endpoints." Glow argues that laptops and workstations
Jul 24, 2026 · via calcalistech.com
With cybersecurity spending expected to exceed $300 billion globally this year, organizations are accelerating their investments in artificial intelligence-based security platforms. Security teams and cybersecurity professionals, however, are confronting issues such as the lack of visibility into how employees are deploying AI across the network. At the same time, the number of AI-based attacks is growing. Specifically, nearly 48 percent of cybersecurity professionals report that they lack visibility into how employees deploy AI tools across corporate networks, raising fresh concerns about "shadow AI" use within organizations. At the same time, attackers are now using these virtual chatbots and other technologies as part of their arsenal, with approximately 52 percent of cyber pros reporting that AI is helping threat actors more than defenders. These results are part of a report released by cybersecurity firm Bitdefender, which surveyed 1,200 IT and cybersecurity professionals, including C-suite leaders, middle managers, and security practitioners. The numbers also show that just a few years ago, AI-based threats were considered mostly theoretical. Now, however, only 17 percent of those surveyed believe that AI attacks are "hyped." Instead, cybersecurity professionals are experiencing numerous threats that use AI technologies, including: - Fifty-nine percent report their organization has experienced social engineering attacks they believe involve AI. - Fifty-five percent report that their organization has experienced malware-based attacks that involve AI. - Seventy percent report that they are seeing more sophisticated phishing attacks powered by AI. In the report, Bitdefender's own researchers detail how one nation-state threat group, APT36, has used an AI-driven development model. Other security researchers documented how a cybercriminal group utilized AI to graduate from small-scale hacking schemes to full-blown ransomware attacks. The Bitdefender report stressed that while an "AI-attack apocalypse" has not materialized, the willingness of attackers and cybercriminals to use AI – as well as employees
Jul 24, 2026 · via dice.com
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The NSA, CISA and partner agencies published a joint advisory on the campaign Thursday, alongside research from Palo Alto Networks' Unit 42 and Proofpoint. The advisory calls the technique "a view-based exploit that only requires a user to view a malicious email" in a vulnerable client. It says the actors have been targeting and compromising Western government and commercial organizations through Zimbra since at least July 2025. The flaw, CVE-2025-66376, is a stored cross-site scripting vulnerability in Zimbra's Classic UI. A crafted HTML email abuses CSS @import handling to execute JavaScript inside an authenticated webmail session, so the payload inherits the user's access to the mailbox. The two CVSS records disagree on whether viewing the message counts as user interaction: NVD scores it 6.1 and says it does; MITRE scores it 7.2 and says it does not. Unit 42 calls it zero-click. All three describe the same behavior: the message runs when it renders, and nothing else has to happen. It affects Zimbra Collaboration 10.0 before 10.0.18 and 10.1 before 10.1.13. Zimbra fixed it on November 6, 2025, and CISA added it to the Known Exploited Vulnerabilities catalog on March 18, 2026. Proofpoint, which tracks the actor as TA488, said the group exploited the bug as an unknown vulnerability for at least five months during 2025, before that fix existed. The patch closes the hole, not the account. An update does not revoke credentials the payload already took. Proofpoint said the messages went out from adversary-controlled
Jul 24, 2026 · via thehackernews.com
For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI models Mythos and Fable. The move was prompted at least in part by a report that claimed it was possible to bypass the models’ guardrails designed to prevent users from using them to build and execute malicious cyberattacks. Regardless of whether the incident was really motivated by fears of a jailbreak, the fact is that Anthropic has repeatedly marketed Mythos as some kind of doomsday cybermachine that can only be given to carefully vetted users, and even then with strict guardrails in place. (The export controls on Fable 5 and Mythos 5 have since been lifted. Fable 5 returned to general access on July 1; Mythos 5 has been reintroduced only to vetted U.S. organizations as part of the government’s review process.) That kind of gatekeeping isn’t unique to Mythos. Both Anthropic, with its other models, and OpenAI offer cybersecurity researchers programs they can apply to get vetted and — if approved — access models with fewer cybersecurity restrictions: OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program. These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do. During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that, “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.” Dowd has spent decades finding and selling “zero-days”
Jul 24, 2026 · via techcrunch.com
PERSPECTIVES FROM THE CAMPUS One of the strengths of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the colleges, universities, and other institutions of higher education throughout our state. Hence the name, “Perspectives from the Campus”, we invite experts – immersed in the pursuit of educating their students – to offer their knowledge for finding solutions in cybersecurity that benefit all Hoosiers. In the latest installment of this series, David Dungan, who serves as the executive director at the Center for Security Services and Cyber Defense at Anderson University, shares his perspective on the cybersecurity threats faced by older Americans and the steps they can take to protect themselves when it comes to avoiding online scams. By David Dungan From managing retirement savings to staying connected with family, older Americans are more active online than ever before. However, this increased connectivity has made them a prime target for cybercriminals. Scammers often view older adults as easier victims, using convincing emails, fake websites, and phone calls to steal money and personal information. Many of these scams are carefully designed to appear legitimate, making them difficult to recognize at first glance. In 2025, Older Americans (aged 60 and older) filed 201,266 fraud complaints totaling $7.75 billion in losses, according to the FBI Internet Crime Complaint Center (ic3) – an increase of nearly 37 percent from the previous year. Investment scams resulted in the highest financial losses, often luring victims with promises of high returns and little risk. At the same time, phishing and spoofing remain the most common methods used by scammers, typically carried out through emails, phone calls, or text messages that appear to come from trusted sources. Despite these growing threats, there are practical steps
Jul 24, 2026 · via in.gov
Many top cybersecurity firms experienced noteworthy rallies throughout Q2 2026, a welcome shift after a period of stagnation for much of the last year up until that time. Companies may be navigating AI upheaval more successfully—Anthropic's Project Glasswing appears to be a model for how traditional cybersecurity companies can partner with AI providers in a mutually beneficial way. On top of this, earnings across the industry have picked up, the result of increased opportunities for attacks on cloud operations and other market-wide vulnerabilities. The takeaway for many investors is that the second half of 2026 could be an opportunity for cybersecurity companies to further distinguish themselves, with various sub-sectors proving ripe for growth and share prices across the sector showing resilience even while a broader AI sell-off has dampened results elsewhere. Cybersecurity exchange-traded funds (ETFs) can help to capture this momentum. A (Relatively) Low-Cost Way of Drilling Down on Cybersecurity Names WisdomTree Cybersecurity Fund Today WCBRWisdomTree Cybersecurity Fund $35.65 -0.97 (-2.65%) As of 07/23/2026 03:58 PM Eastern - 52-Week Range - $22.49▼ $41.14 - Assets Under Management - $105.38 million With returns of more than 35% year to date (YTD), the WisdomTree Cybersecurity Fund NASDAQ: WCBR is an information technology fund with a specific focus on companies involved in the cybersecurity space. Its basket is fairly narrow, as the fund holds only 33 positions. However, even the largest allocation—to industry leader CrowdStrike Holdings Inc. NASDAQ: CRWD—is only about 7.7%. This makes the basket a way to gain access to a moderately evenly-weighted collection of the biggest and most successful global cybersecurity companies trading today. WCBR is not the largest cybersecurity ETF by any means. Indeed, its $111 million in managed assets and similarly modest trading volume suggest that many investors overlook this fund. Still, with an expense ratio of 0.45%,
Jul 23, 2026 · via marketbeat.com
OpenAI hacking incident highlights new era of cybersecurity LAS VEGAS (KSNV) — OpenAI said Tuesday that one of its artificial intelligence systems autonomously hacked into Hugging Face during a test designed to see whether the model could break into a target system, raising new questions about how quickly AI-driven cyber capabilities are advancing and how they should be governed. RELATED CONTENT: Most teens fear deepfakes amid widespread exposure to AI sexual content: survey John Amar, owner of NextTec, said OpenAI was testing a new model and “they were attempting to run it through an internally developed test to see if it could hack something,” and that it did — successfully hacking into Hugging Face, an AI startup. Hugging Face CEO Clement Delangue said, “We strongly believe there was no malicious intent on their part. It’s quite mind-blowing that all of this happened autonomously.” Amar questioned whether the incident should be described as a system “going rogue." “Is it rogue if it’s able to do the thing that it was attempting to do, maybe, maybe not, I’m not sure.” Sean Connery, chief security officer of Orbis Solutions, said he expects the incident to accelerate changes in cybersecurity. “We’re seeing that attackers are using AI, that defenders are using AI and the race between the two is escalating,” Connery said. Amar also warned that advanced capabilities are not limited to major companies. “There are tons of open source models out there already that have probably similar capabilities that are already as advanced.” Experts said the bigger concern is not AI itself, but who might use it. “I think what this demonstrates is how it will make it a lot easier for people to hack systems," Amar said. Connery and Amar said they believe more guidelines are needed around artificial intelligence. “I haven’t
Jul 23, 2026 · via news3lv.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jul 23, 2026 · via youtube.com
Financial Beat & Cyber Growth McDermott emphasized that ServiceNow is rapidly expanding beyond traditional IT workflows into security orchestration, accelerated by recent acquisitions like Armis and Veza. “We now have a 10-figure cybersecurity business that’s growing faster than all the other top cybersecurity companies,” McDermott stated during the earnings call. He added that the performance solidifies ServiceNow’s position as the “fastest-growing major enterprise software and cybersecurity company,” declaring, “We are who we said we were: a defining company that is only just getting started.” The enterprise software provider delivered non-GAAP earnings of $0.90 per share, topping Wall Street expectations of $0.85 per share. Following the strong second quarter performance, ServiceNow raised its full-year 2026 subscription revenue guidance to $15.77 billion, representing 21% year-over-year growth. Accelerating Enterprise AI Adoption ServiceNow’s AI annual contract value (ACV) crossed $1 billion during the quarter, keeping the firm on track to hit $1.5 billion by year-end. Management reported that deployments of agentic AI increased ninefold over the last nine months. Current remaining performance obligations (cRPO) closed at $13.20 billion, up 21.5% year-over-year in constant currency. Analyst Perspective on AI Moat Boloor added that ServiceNow acts as the control layer for “any agent, any workflow, any model,” highlighting that 50% of the company’s net new business is already non-seat-based. How Has NOW Performed In 2026? NOW shares declined 37.69% year-to-date, up 2.63% over the last month, and lower by 50.40% over the year. It closed 6.47% lower at $95.46 per share on Wednesday, and it was up 7.24% in premarket on Thursday. Benzinga’s Edge Stock Rankings indicate that NOW maintains a weak price trend in the short, long, and medium terms, with a solid growth score. Photo courtesy: bluestork / Shutterstock.com © 2026 Benzinga.com. Benzinga does not provide investment advice. All rights reserved. To add Benzinga
Jul 23, 2026 · via benzinga.com
Abstract AI-driven anomaly detectors in 5G renewable energy IoT and industrial systems lack unified governance: they operate opaquely, exhibit protocol-class bias, and expose training data to inference attacks. This paper presents the Ethical AI Governance Framework (EAGF), which maps four EU AI Act pillars, transparency (C), fairness (RP/FPRP), privacy (P), and accountability (A) to computable engineering metrics that are jointly governed within one training-and-deployment lifecycle: fairness and privacy are co-optimized via a Pareto-guided multi-objective procedure with domain-adaptive fairness loss selection, transparency is structurally controlled through clarity-triggered pruning, and accountability is audited post hoc, with all four scores aggregated into a composite Trust Index (TI). Evaluated across two domains: on a biometric task (10,021 images, ten seeds), EAGF raises TI by \(+38.97\%\) (\(0.565\rightarrow 0.785\)), improves recall parity by \(+15.1\%\), and enhances privacy by \(+18.8\%\); on the real-world Edge-IIoTset intrusion-detection benchmark (157,800 samples, five seeds), EAGF achieves \(+69.3\%\) TI gain (\(0.358\rightarrow 0.606\)) and \(+56.4\%\) FPR parity improvement, with only \(+0.2\) ms forward-pass inference overhead. Joint multi-pillar governance substantially outperforms model-level-only approaches across both domains; the accountability infrastructure contributes a large and explicitly quantified fraction of total TI gains, underscoring that governance readiness requires both algorithmic and operational investments. Acknowledgements The authors thank the contributors of the Edge-IIoTset dataset and the open-source community for supporting reproducible and transparent AI research. Author information Authors and Affiliations Corresponding author Ethics declarations Ethics approval and consent to participate This study uses publicly available datasets and does not involve direct human subject experimentation. All datasets were used in accordance with their respective licenses and ethical guidelines. Competing interests The authors declare no competing interests. Additional information Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. Supplementary Information Rights and permissions Open Access This article is licensed under a Creative
Jul 23, 2026 · via nature.com
Intel and Fortinet team up on SP6 cybersecurity chip Intel and Fortinet have expanded their long-standing partnership with a strategic collaboration to develop Fortinet’s next-generation Security Processor 6 (SP6), combining custom cybersecurity silicon with Intel’s semiconductor design, packaging and manufacturing capabilities. The collaboration is aimed at accelerating development of the SP6 ASIC while also improving the resilience and diversity of Fortinet’s global supply chain at a time when security infrastructure and semiconductor sourcing have become strategic priorities. For eeNews Europe readers, the announcement highlights two key trends: the growing role of custom silicon in cybersecurity appliances and the increasing importance of supply chain resilience in semiconductor manufacturing. It also reflects how chipmakers are positioning advanced packaging and manufacturing services as strategic assets beyond traditional processor products. Custom silicon for next-generation security The partnership brings together Fortinet’s experience in purpose-built security processors with Intel’s expertise in semiconductor design, ecosystem IP, advanced packaging and manufacturing. The companies say the goal is to accelerate the development of the SP6 processor while enabling more sophisticated security services and higher performance for enterprise deployments. According to Intel, the collaboration will also support a more diversified manufacturing strategy for Fortinet, helping reduce supply chain risks while expanding production capabilities. “As organizations face a rapidly evolving threat landscape, security infrastructure must deliver both performance and innovation at scale,” said Lip-Bu Tan, CEO of Intel. “This collaboration demonstrates how Intel’s semiconductor leadership and advanced design, packaging, and manufacturing capabilities can help cybersecurity leaders like Fortinet accelerate the development of critical security technologies while building a more resilient and diversified global supply chain.” Fortinet has relied on proprietary ASICs for more than two decades as a way to improve the performance and efficiency of its networking and cybersecurity platforms compared with software-only implementations. Beyond manufacturing The collaboration extends beyond
Jul 23, 2026 · via eenewseurope.com
FedRAMP has accepted its first rotational employee from another federal agency as the cloud security program works to launch its new FedRAMP Cybersecurity Service despite hiring challenges, FedRAMP Director Pete Waterman said Thursday. Speaking on July 23 at GovForward’s Carahsoft FedRAMP Summit in Washington, D.C., Waterman said FedRAMP accepted the rotational employee last week. “We have someone that just started at FedRAMP that works at another agency. They’re coming over to us for four to six months to learn how we’re doing things, so they can go back to their agency and help their agency move faster,” Waterman said. “We’re super excited about that.” Waterman first announced plans for the FedRAMP Cybersecurity Service in January as part of the program’s broader FedRAMP 20x modernization effort. The FedRAMP Cybersecurity Service aims to hire 15 employees for two-year terms of service. In an exclusive interview with MeriTalk earlier this year, Waterman shared more details on the program. The vision, he said, is a rotating workforce model that would blend career federal staff with detailees and private-sector experts to keep technical expertise current. FedRAMP officially opened applications for the initial cohort of four lead cloud security engineers on May 4. However, on Thursday, Waterman said the FedRAMP Cybersecurity Service has “run into some glitches in the hiring process.” Waterman has also publicly detailed those hiring challenges. In a LinkedIn post last week, he said FedRAMP officials had expected to evaluate applicants based on their specialized cloud security experience but were instead told that only applicants eligible for veterans’ preference would initially be considered. Waterman wrote that FedRAMP did extend an offer to one qualifying applicant and is interviewing additional candidates. Still, he stressed that the program ultimately needs the ability to recruit engineers with direct private-sector cloud experience. “The future for FedRAMP is
Jul 23, 2026 · via meritalk.com
GAO Confirms Cyber Reporting Burdens as CIRCIA Rules Loom The Government Accountability Office (GAO) released on July 22 a comprehensive assessment of federal cybersecurity requirements, and its conclusion will sound familiar to many regulated companies: overlapping requirements are widespread, reporting obligations are duplicative, and harmonization efforts have not worked. In its report, Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements (GAO-26-108606), GAO examined cybersecurity regulations affecting private sector entities across critical infrastructure and found a substantial amount of potential for duplication and conflict across the federal government. The report arrives at a particularly apt time, as the Cybersecurity and Infrastructure Security Agency (CISA) moves toward finalizing new reporting regulations under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). GAO Finds Substantial Regulatory Overlap GAO identified a whopping 117 existing cybersecurity regulations administered by 37 federal agencies across nine critical infrastructure sectors. Of those, it found that 80 regulations (about 70%) have affirmative reporting requirements, collectively imposing at least 125 separate reporting obligations on private sector entities. These obligations include cyber incident reporting, submission of cybersecurity plans and technical information, and reporting related to audits, reviews, and assessments. The report found that many regulations require regulated entities to provide similar information to different federal agencies, such that companies may need to prepare multiple reports concerning the same cybersecurity event or compliance activity. GAO highlighted potential overlap across all three reporting categories, including 48 regulations requiring cyber incident reporting, 52 requiring cybersecurity plans or technical information, and 25 requiring audits, reviews, or assessments. (And this does not even touch on state obligations, which are proliferating). This figure from the GAO report shows the number and nature of the requirements: GAO's findings reinforce concerns that industry and cyberattack victims have raised for years. As Wiley previously observed,
Jul 23, 2026 · via wiley.law
With the right foundation in place, the journey to a more resilient, AI-powered SOC needn’t be daunting. The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES). AES represents a paradigm shift, moving security from a passive monitor to an active participant in the defense lifecycle. It provides the visibility and automated guardrails necessary to govern autonomous AI agents and agentic tools, ensuring that as your workforce scales with AI, your security posture remains unbreakable. With autonomous AI agents now capable of planning and executing multi-stage attacks at machine speed, the pressure on traditional security operations (SOC) has reached a breaking point. To survive this shift, the strategy is clear: we must fight AI with AI. Here is how AI-driven defense, pioneered by Cortex XDR and the era of Agentic Endpoint Security, is fundamentally rewriting the cybersecurity playbook. - From reactive patching to proactive prevention For decades, the industry lived in a “wait-and-see” mode waiting for a vulnerability to surface, waiting for a signature, and then rushing to patch the hole. But reactive methods just don’t hold up against modern “frontier” AI attacks that are constantly morphing. AI-driven defense changes the game by shifting to a prevention-first architecture. Rather than relying on historical signatures, modern platforms deploy localized, ML-driven analysis to evaluate the intent and behavior of an active process, stopping threats pre-execution. Cortex XDR leads with a strict prevention-first approach by using AI-driven local analysis and behavioral threat protection; the XDR agent stops sophisticated threats pre-impact and pre-execution. This proactive stance reduces the overall risk profile by blocking malicious chains of
Jul 23, 2026 · via csoonline.com